Out-of-Bounds Affecting quickjs package, versions *


Severity

Recommended
low

Based on Debian security rating.

Threat Intelligence

EPSS
0.01% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIAN13-QUICKJS-13849488
  • published7 Nov 2025
  • disclosed5 Nov 2025

Introduced: 5 Nov 2025

NewCVE-2025-12745  (opens in a new tab)
CWE-119  (opens in a new tab)
CWE-126  (opens in a new tab)

How to fix?

There is no fixed version for Debian:13 quickjs.

NVD Description

Note: Versions mentioned in the description apply only to the upstream quickjs package and not the quickjs package as distributed by Debian. See How to fix? for Debian:13 relevant fixed versions and status.

A weakness has been identified in QuickJS up to eb2c89087def1829ed99630cb14b549d7a98408c. This affects the function js_array_buffer_slice of the file quickjs.c. This manipulation causes buffer over-read. The attack is restricted to local execution. The exploit has been made available to the public and could be exploited. This product adopts a rolling release strategy to maintain continuous delivery Patch name: c6fe5a98fd3ef3b7064e6e0145dfebfe12449fea. To fix this issue, it is recommended to deploy a patch.

CVSS Base Scores

version 3.1